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gXELD op THE HO ffiMZIQM 

The present invention relates to a method for providing an 
authentication to an application. The invention relates 
further to an arrangement for providing an authentication 
co an application and further to an apparatus to be used 
in che authentication . 

BACKGEQI3H D ^ THE tnv-NTTON 

Various electronic applications exist which involve a need 
for an authentication. Authentication may be required, 
for example, when a user is accessing a specific 
application and/or when a user already uses an application 
and there arises a need to verify the user or to receive 
such an acknowledgment from the user which allows the 
application to make some further proceedings. 

Examples of applications which might require an 
authentication include various commercial services 
ob-ai'ned through communications networks, such as 
ZZZ, intranet' or Local Area Networks (LAN) payments 
and bankinc services accessed through communications 
networks, resource access, remote programming, 
reorogramming or updating of software etc. Even certain 
f~e of chare, services obtained through a communications 
networks may" require an authentication. The amount of 
services or applications which require at least some 
decree of authentication of the user who is trying to 
access them (or of the user who is already using them but 
wbe .e there is a need to check authorisation curing the 
use of fne service or a need to acknowledge something 
during the use) has increased greatly during the past 
y .ars The need for the authentication is also expected 
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to increase further in the. future. 

At present there are already some well known solutions for 
ITnication authentication. These —ally use various 
cryptographic techniques between two communxcatxng 
colter devices. According to a basic scenarxo for the 
authentication, a random challenge is S i-^cn 
functions of said two computer devxces . Both of these 
functions encryption key, whxch xs 

computers have a secret, x 
, also given to the encryption function xn both of the 
5 coders. Thereafter, the results of the ^1-, of 
^he two encryption functions are compared, and xf the 
^fsult of . thf comparison is positive, the 
I; considered as being in force. If the comparxson gi ves 
5 a, negative result, then the authentication test 
considered as having failed. 

There are also various already existing authentication 
Tnere are followin g examples of the prxor art 

arran !"a re g.ven with a brief description of some of 
20 arrangemenca axe y- v ^ 

the drawbacks thereof : 

-* 

Passwords. A, presenc , eh. use of a P"-~»» » 
several passwords is the most often used approach r 
;J authentication. The password is given to tne re °t 
aoplication through an user interface, eg. through a 

coLuter terminal connected to a =« ^^ITlZ of 

j _ ^_ t-^ir^ the vulneraDiiii-y ^ ^ 
However, this solution doe not take th ^ 

che network into account since the p skiU . e d 
30 everyone who has access to the network (and who is 
enough to read the passwords) . 

A secret. This may be described as an 
password or a signature or an encryption Key which IS 
3, stored and used by for example the user interface. Even 
Chouoh the secret is not revealed to the network, it may 
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• in the "wrong hands" and could be used by some 
ena up in tne wro y nri ainally intended to be 

carry other than those who are originally 



parry 

the users of the secret 



AuCh entication software in the 



This 
The 



10 



15 



Authentication — ,u an r^ation 

is . more sophisticated approac * » »^ tic on^ 

— " " ^^S.^ ^graphically 

i::i:;rr::::::e/a PP uca trt rr: -- 

■ more secure arrangement than tne 
provides a more seour . , r cat ching the 

solution, it still leaves a possibility fo ^ ^ 
oasswords from the user interface. It * P 
modify the software without notice to the 

smart cards with associated readers. A smart card is 
c^TS communicating encrypted --^^ 
messages, hut it does not contain a user ^ ^ 

receiving an — ^ ^ ^ r£aders . but such 
interface may exist m tne possibilities 

= v->p well protected against any p 
readers must be well P ^ ( . e ^ large 

;cr misuse and tnus have 

majority cf users, re. . „ rf .„ s but they have 

■ •• -=,1 -cess to these reader interfaces, 
p ,ysica access provi ding the smart cards. 

" trUS \ C ° smart card readers cannot be shared 

; in addition, the smart <=* each 
between organizations which do not have 

others . • .- . 

interface These do already 
qmar ca rds with a user interface. 
Smar. car sive sinC e each security 

,0 exist, but they ^re expensi terfaC e of it's own. 

- processor must have a secure user . thereof is 

« =nrl the input/output capability tnere 
These are rare and the mp / ^ to be 

still extremely limited,- and .hus they ation 
an economically suitable solution for 
55 problem . 
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A separate personal authentication device. In this 
approach the user is used as M a communication means" 
between the user interface and a separate authentication 
device. The user interface gives a challenge which the 
user then types in to a hand held authentication device 
(pocket -calculator like device) . The authentication 
device may, eg. give a number as a response, and the user 
then types this number in to the user interface. In this 
the problems relate to the need of purchasing, using and 
carrying a separate device. In some instances there is 
also a possibility of incorrect typing of the usually long 
and complex character strings. 

The above already mentions some parties which may be 
involved when implementing the present authentication 
systems. They are briefly explained in more detail in the 
following : 

The user is usually a human being who uses various 
applications or services. The user can be identified by 
means of a password (or secret) which is only known by 
him/her (a public key method) , or by means of a secret 
which is shared between the user and the application (a 
secret key method) . 

The application is the party that wants to ensure the 
authenticity of the user. The application can also in 
some occasions be called as a service. From the 
application's point of view the authenticity question can 
be divided in four different categories (questions) : 1) is 
the user at the moment in the other end? (so called peer- 
entity-authentication) , 2) are the further messages 
received from the same user? (integrity of the message 
stream) , 3) does a specific message originate from a 
certain user? (data origin authentication), and 4) is the 
message such that even a third party may believe it to 
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originate fro* a certain user? (non-repudiation) . 

Th e user interface is the device or arrangement which 
enables the user to access the appiication or servrce In 

3 Tost instances it can aiso he referred to as . terminal, 
and may consist of devices such as computers (eg . 
Personal Computer, PC,, workstations, telephone terminals, 
lool^ stations such as mobile telephones or radios or 
Tage:; automatic money teller and/or banking -hrnes. 

,„ etc The user interface provides input/output facrlrtres 
and it may possibly even provide a part of the 
application. 

The =e~sor.al Authentication Device ( PAD) is a piece 
of hardware" that che user carries with him. The PAD may 

Che user possib le passwords or secrets 

continuous control. All cne p 

are hidden in the hardware thereof such that there rs 
easv manner to reveal them. The device xt«l 
to modify such that the communication path between the 
ser an/the security processor could be endangered. In 

addition, tne PADS usually ^ ^^^Z^^T. 
scats and the programs thereof are not ea S1 y 

SXJKM&EV o- TH E INttEHXIDSI 

S ven though the above described prior art solutions for 
authentication already exist, there are still some 
3t n addition to those already referred to above, 

shcrtaaes, m aaaicion 

in the" area of authentication. 

in case the access to the application is made absolutely 
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secure, or as secure as possible, the application easily 
becomes extremely complex from the architecture thereof, 
and becomes also complicated and more time consuming to 
access and use. The increased security level increases 
5 the amount of the required hardware and software, which 
leads to an increased need for maintenance and updating 
thereof, and thus the total costs* of the authentication 
may become high. The complexity and costs could be 
decreased by lowering the level of security, but this is 

10 expected to lead to an insufficient security level in the 
communications. In addition, it is believed that an 
"absolutely secure" condition does not even exist in the 
communications networks, as the technical development 
makes it possible for hackers to solve even the most 

15 complicated security arrangements. 

A human problem lies on the fact that the passwords or 
secrets may become quite complicated and/or too long, or 
that there may be too many of them. Thus the users may 
20 find it hard to remember them. Typically a secret which 
is considered as secure in the secret key method is 128 
bits and in the public key method it is 1024 bits. For 
most people it is impossible to remember this kind of key. 

25 In addition, users are not able to perform the 

calculations required in the authentication without 
external devices. As was explained above, the basic 
authentication is of cen made by challenge and response 
method. This would require the user (ie. a human) to 

30 encrypt something with his secret. This is not held to be 
possible in practice 

In addition to the possibility of catching the password or 
secret during it's transmission over an open 
35 communications network as was discussed above, today's 
solutions do not pay sufficient attention the 
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i wiitv o* the user interfaces either. The terminal 
vulnerability o. tne ^ technology 

devices have developed to be tun v lrt ™ r 

and software such chat most of the users are no longer 
raDable of fully controlling. the terminals, or 
capable or y thereo f In addition, it 

understanding the operation thereor . 

device (ea. is a . commonly used PC) and/or 

" na1 has access to the computers of a per 

maintenance personnel has access 

se closed organization. 
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The co.pu.er terminals contain store* 

\, m .-. s thereof, which can be modified. 
in tne « - ^ possible to m odify the software 
modern computer- - - P° nocice this , and 

ss to The device itself. To give an example of the 
access to the ae ^ b ^ . compuc 

risKs. rt is p-s fies che daca the user sends for 

terminal sucn n.. " er raodi£ies ail ban, 

example to a banK such that ^ ^ 

rrarsfers on a certain aciy 

- ■ w the user. This modifying or 

was cesignatec b, the us s , riou s and huge 

Programming without notice may cause s r 

damages when used against ordinary individual users, 
eso-cialiy when used against organizations such as . 
esjvtiai./ TVii= all means tnat 

•«.«= ru^ic administration. This all me* 
companies or pa~-ic nat h S 
" ror -inal devices and communication patns 

the ordinary ter...mai aev.^ 

cannot be trustee. 

_ - i- = ~ object of the present invention to 

Therefore u .s ob 3 solutions and 

, ov»-com- the disadvantages of the prior art 
to'provide a r.e, type of solution for 

A n object is also to provide a .ethod and an arrangement 
f u h c v a user who wishes to access an 
5 Z£ZZ c^ authenticated in a m ore secure .anner 
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than has been possible in the prior art. An object is 
also to provide an authentication when a need for the 
authentication arises during the use of an already 
accessed application, 

5 

An object of the present invention is also to provide a 
method and arrangement by means of which a mobile station 
can be utilized in the authentication. 

0 An additional object of the present invention is to 

provide a solution in which an identification module of a 
mobile station can be utilized in the authentication. 

Other objects and advantages of the present invention will 
5 be brought out in the following part of the specification 
taken in conjunction with the accompanying drawings. 

The objects are obtained by a new method for providing an 
authentication to an application provided through a 

0 communications network. According to the present 

invention a connection between the application and a user 
interface through said communications network is 
established so as to enable' an access of a user to the 
application provided through the communications network, 

15 while an authentication to said application is provided by 
means of a mobile station communicating through a mobile 
communications network . 

According to one further embodiment the authentication 
30 method comprises a step of establishing a connection 
between an application and a user interface through a 
communications network so as to enable an access of a user 
tc the application provided through the communications 
network. The authentication to said application is 
35 provided by means of a mobile station such that a secret 
of a Subscription Identification Module (SIM) of the 
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ile station is utilized in encryption operations of the 



mob 

authentication . 
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The invention provides further an arrangement for 
providing an authentication to an application provided by 
an application provider through a communications network. 
The arranoement comprises a user interface and a 
connection between the application and the user »"rf«=. 
through said communications network so as to enable use of 
«*- application. The arrangement further comprises means 
for authenticating the use of the application, wherein 
said means for authenticating comprise a mobile station 
communicating through a mobile communications network and 
a link between the application implemented by the 
communi=ations|network and the mobile communications 

network. 

According to an alternative embodiment the invention 
provides a mo bile station for providing an authenticate 
to an application provided through a communications 
network. In this embodiment the application is accessed 
bv means of a user interface connected. to the 
communications network, while said mobile station is using 
a different communications network for the communications 
than the user interface. Said mobile station is used for 
authenticating the use of said application accessed by the 
user interface. 

Several advantages are obtained by means of the present 
, invention, since the solution introduces a new reliable 
n-.anr.er for authentication. The inventive authentication 
method and arrangement is easy to implement in already 
existing communications networks without any excessive 
alternations or additional devices. The arrangement can 
, be used in connection with various different applications, 
in practice in connection with any such application 



WO 99/44114 



PCT/EP99/00763 



■10- 



10 



15 



20 



30 



provided through a communications system which needs some 
kind of authentication. 

The user is freed from carrying a separate authentication 
device (PAD) or many different authentication devices. 
The user can also trust to the personal authentication 
device (PAD) according to the present invention, as the 
mobile station is usually always with him, and the users 
tend to take good care of their mobile stations. In 
addition, for instance in case of theft of a mobile 
station, the mobile subscription and/or the SIM thereof 
can be' easily canceled by the operator. All secrets of a 
mobile station are well hidden in the hardware thereof 
such that it is not easy to reveal them. In addition, the 
mobile station device itself is not easily modifiable in 
such a way that the communication path between the user 
and the security processors could be endangered. 

The system includes a minimum amount of stored state and 
the programs "are not easily modifiable. The existing SIM 
of a mobile station, and more precisely the secret 
tbe-eo*. can be utilized for the required encryption 
procedures.' Thus the SIM can be utilized as a security 
card for new purooses, and there is already an existing 
party who will control the use of the SIM, ie . the mobile 
network operator who can immediately cancel a SIM if fraud 
is suspected. 

In the following the present invention and the other 
objects and advantages thereof will be described by 
examples with reference to the annexed drawings, in which 
similar reference numerals throughout the various Figures 
refer to similar features. It should be understood that 
the following description of the invention is not meant to 
restrict the invention to the specific forms presented in 
this connection but rather the present invention is meant. 
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to cover all modifications, similarities and alternatives 
which are included in the spirit and scope of the appended 
claims . 

5 rptpf DESCRIPTION of thf. DRAWINGS 

Figure 1 shows a general view of one possible arrangement 
of communications networks in which it is possible to 
implement the present invention ,- 

10 

Figure 2 is a schematic presentation of an embodiment for 
authenticating a user according to the present invention; 

Figure 3 discloses schematically one possible mobile 
15 station and an embodiment of the present invention; 

Figures 4 and 5 disclose flow charts according to two 
embodiments of the present invention; 

20 Figure d discloses an alternative embodiment for the 

authentication in accordance with the present invention; 
and 

Figure 7 is a schematic presentation which relates to a 
25 further embodiment of the present invention. 

p?Ta TT.Fn nps^ PTPT T nM np> THE DFAWTNGS 
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Figure 1 is a schematic representation of one network 
arrangement which can be used when implementing the 
present invention. The arrangement of Figure 1 comprises 
a Public Switched Telephone Network (PSTN) which is 
schematically shown as a box designated by 20. The 
exemplifying PSTN is a fixed line telephone network (or 
35 Plain Old Telephone Service, POTS) , which forms a 

communications network through which a user interface 16 
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is enabled to access an application. According to this 
embodiment a user (not shown) may use the user terminal 16 
connected to the PSTN as a user interface to access to the 
desired service in one of the WWW servers 4 5 obtainable 
through an Internet connection. The disclosed terminal 16 
is a personal computer (PC), but other types of user 
interfaces, such as workstations, automatic public teller 
machines etc. may also be used. 

A Public Land Mobile Network ( PLMN) is also disclosed. 
This may be, for example, a cellular telephone network or 
similar mobile communications system. Two mobile stations 
MS 1 and MS+PC 2 are also disclosed. The MS + PC 2 may be 
defined as an integrated mobile phone and a portable 
15 computer. Both of these are capable of communicating 

through an air interface 3 with the PLMN through one of 
several base stations (BS) 4 of the PLMN. 



10 



20 
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One type of PLMN is a digital GSM network (GSM; Global 
System for. Mobile Communications), which is well specified 
in the GSM recommendations by ETSI (European 
Telecommunications Standard Institute), the network 
architecture thereof being described in detail in 
recommendations GSM 01.02 or GSM 03.02 or the revised 
versions thereof. It is to be noted that while the 
invention is mainly described in the context of an 
exemplifying cellular telephone network using GSM 
terminology, those skilled in the art will appreciate that 
the present invention can be implemented in any mobile 
system. Furthermore, it is to be noted that for clarity 
reasons only those parts of a mobile network structure are 
shown which are considered as necessary for the purposes 
of illustrating the operation of the exemplifying system. 
The skilled person is well aware of the fact, that the 
telephone networks may normally comprise also other 
necessary apparatus than those illustrated, that some the 



WO 99/44114 



PCT/EP99/00763 



-13- 

disclosed elements of Che PLMN or PSTN may be omitted or 
replaced by some other type of elements, and that a great 
number of mobile networks and ordinary fixed land line 
networks may cooperate and interchange with each other. 

5 The skilled man understands also that the connection to 
the Internet may also be a direct connection without any 
PSTN or similar network arrangement between the user 
terminal 16 and the Internet 43. These alternatives are, 
however, not shown and explained in more detail as they 

10 are known to skilled man in the art. 

The GSM based public land mobile network (PLMN) usually 
includes several mobile service switching centers (MSC) 
10. Each of these is, in turn, connected to a plurality 

15 of base station subsystems (BSS) 6 (only one MSC and BSS 
is shown for clarity) . The base station subsystem' 6 
usually comprises a base station controller BSC and 
necessary interface apparatus, and is connected to a 
plurality of base stations (BS) 8, each of which 

20 supervises a certain geographical area , referred to as a 
cell (for the cells, see Figure 7). 

The mobile services switching center 10 of Figure 1 is 
further connected or linked to the public switched 

25 telephone network (PSTN) 20 through an exchange 12 and 
lines 12. The MSC 10 is also connected to a global 
communications network, which in the example is the 
Internet (designated by numeral 43) . The MSC may be 
connected to an integrated services digital network (ISDN) 

30 or any other type of appropriate communications network. 
The necessary links between different components of 
different telecommunication network systems are per se 

•.veil known in the art. 

35 The PLMN network includes further a database, the so 

called home icca:ion register (HLR) 9, which is connected 
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to the MSC. Those mobile terminals 1 and 2 which are 
subscribers of the mobile telecommunications network are 
registered in the HLR 10. Each local mobile telephone 
switching center 10 includes further a local database 
5 called a visitor location register (VLR) 8, into which is 
registered all such mobile stations 1 and 2 which are 
located within the area of one of the cells handled by 
that local mobile telephone services switching center MSC 
at any given moment . 

The mobile stations are identified by a SIM (Subscriber 
Identification Module) which is usually mounted within 
each of the mobile stations, or otherwise physically 
connected thereto. A SIM is a module which includes 

15 various user (subscription) related information and 

secrets. It may also include further information which 
relates to the encryption of the radio communications. 
The SIM may be assembled fixedly or removably to the 
mobile station. The utilization of the SIM as well as the 

20 KLR and/or VLR registers in this invention will be 

discussed in more detail later in this specification. 

As discussed, :he user may be connected. to the Internet 43 
via a fixed or a mobile network or via a direct 

25 connection. However, there may be some differences 

between the connections when for example GPRS (General 
Packet Radic System) is concerned, but the service from 
the Internet network is available for the users of both 
PSTN and PLMN systems. In the example, the Mobile 

30 Switching Center (MSC) 10 as well as the PSTN 20 are 

provided with an access to the multiprotocol Internet 43 
by access nodes (AN) 14 and 40. Even though only one AN 
per communications network is disclosed, it is to be 
understood that in practice the number of ANs may be 

35 essentially greater, and that the number of ANs is also 
increasing continuously. According to one solution a 
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special internet Access Server IAS capable of converting 
the signal into data packets is used as an AN towards the 
Internet . 

The users of the Internet 43 have made a contract with a 
Internet Service Provider (ISP) 42, who provides the 
communications connection to the Internet from the user 
terminals 1, 2 or 16 . When the user desires to have an 
Internet connection, he calls to the Internet Service 
Provider ( ISP) 42 so as to connect his terminal 16 to the 
desired address (so called Internet Protocol address) . 
The call connection is established by the PSTN 20 and 
passes through at least the local exchanges 18, and 
perhaps one or several transit exchanges which are 
connected or interconnected through trunk lines (not 
shown) . It is to be understood that even though Figure 1 
discloses only one ISP through which both networks 
communicate towards the Internet, communication could be 
arranged through different ISPs. 

Figure 1 discloses further a WWW server 45 (World Wide Web 
server) which includes server databases. x, y and z 
providing different services. It discloses also a 
connection fro- the ISP through the router 44 to said 
server 45 via ".he Internet 43. It is to be understood 
that the service can be any service obtainable through any 
communications network, such as a banking service, an 
electronic shopping service etc., in which authentication 
is required. 

The mobile sta:icn 1 (or 2) is used as a personal 
authentication device (PAD) when the user accesses, or has 
alreadv accessed, via the user interface 16 through the 
PSTN 20, a service x provided by the WWW server 45. The 
mobile station 1 communicates with the service x through a 
separate communications path or channel than is used by 
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the actual user interface 16. The mobile station can be 
trusted because the user usually keeps it always with him. 
The ergonomic and functional requirements for the mobile 
stations and for the conventional PADs are essentially the 
5 same, and the MS has a user interface that is suitable for 
the PAD. A modern MS has even a security processor 
interface that is suitable for authentication purposes. 

There are several alternatives to accomplish the 
10 authentication by means of the mobile station, and the 

examples thereof will be now discussed in the following in 
more detail. 

Reference is now made to Figures 2 and 4 , of which Figure 
•l> 2 discloses schematically one arrangement for the 

authentication, and Figure 4 a flow chart for the operation 
in accordance with one basic embodiment. The user 22 
sends a request by means of the user terminal 16 to access 
a desired application 45, such as a banking service, 
20 through a connection established by means of a 

communications network (arrow 21 in Fig. 2; steps 102 and 
104 in Fig. 4). The application 45 may comprise a 
database 46, or is connected co a separate database, such 
as the HLR 9 of the MSC 10 of Fig. 1, from which the 
25 application is enabled to retrieve the necessary user 
information. On the basis of this information the 
apolication establishes a connection to the mobile station 
• 1 "of the user 22 (arrow 26; step 106) for authentication 
ourposes. At this stage the user may accept the 
30 connection 21 made by the user interface 16 by sending 
back a confirmation signal 29 (ie. an acknowledgment) 
using the mobile station 1 indicating chat access is 
allowed and that the actual use of the service may begin 
(steos 108 and 112) . In case the authentication fails, 
35 ec 'on the basis that the application cannot reach the MS 
l" ail connections are closed (step 110). Alternatively 
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the user may be allowed to retry the access, either 
immediately or after a certain time period, or the user 
may be instructed by the user interface 16 to take some 
additional measures due to the failed authentication. 

One way to implement the authentication, or the 
acknowledgment feature, is to use short messages of a 
short message system (SMS) of the PLMN . In the GSM 
system, a SMS MSC (SMS Message Service Center) designated 
by 7 in Fig. 1 is provided for the delivery of short 
messages to and from the mobile stations. The service 
center 7 sends the messages to the mobile subscribers 
using the same network elements as were discussed above 
and defined by the referred specifications. The SMS 
message signaling usually contains, eg. the receiver 
identification, sender information, time stamp etc. 

Figure 3 discloses a solution in which the mobile station 
MS 1 has received a SMS message. The method steps for 
this are shown by the flow chare of Figure 5. According 
to this embodiment the user has requested, after having 
accessed the banking service through the user interface 
16, that a sum of 200 FIM should be transferred from 
account No. 1234-4567 to an account No. 4321-7654 (seep 
204) . The application retrieves the user related 
authentication data from an appropriate database (step 
206), and sends accordingly a text message to the mobile 
station 1 (step 208) . The MS 1 displays the text as . 
shown, and asks the user to confirm or to deny the 
transaction by pressing "Yes" or "No" keys, respectively 
(step 210) . The response is then transmitted back to the 
application, and in case of "Yes" the transaction proceeds 
(step 214) and in case of "No" some other measures are 
taken . 



3:> 



The arrows 27 and 28 of Figure 2 can also be seen as 
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illustrating the stage in which the MS 1 and the user 2 
communicate: information received by looking at the 
display 31 of the MS 1 is indicated by arrow 27, and the 
response given by the user to the MS 1 is indicated by 
arrow 28. As explained, the user may choose a proper 
selection by pressing either Y or N key 32 of the MS. In 
case the user accepts, ie. "signs" the transaction, the 
banking service will then proceed accordingly. In case 
the user will not confirm the transaction, ie . presses the 
"No" key, the application may send a request to the user 
interface to feed in a correction, a cancellation, a new 
destination account etc. (steps 216, 218) . 

In case the application does not receive any response 
within a certain time period, or the response is somehow 
incorrect, the application may either send a second 
request for the confirmation, or close down all the 
connections . 

The user may process several subsequent transactions and 
even some other banking services after having once 
accessed the application. When the user finally replies 
at step 216 to the user interface 16 that he does not want 
to continue, the connections are closed (step 220) . 

According to one embodiment of the present invention the 
information contained in the HL?. and even in the VLR of 
the PLMN of Figure 1 can be utilized when implementing the 
inventive authentication arrangement. This is enabled by 
the fact that each of the mobile subscriptions includes, 
in the HLR 9 of Figure 1, information relating to the SIM 
(Subscriber Identification Module) already referred to, an 
IMSI (International Mobile Subscriber Identity) and MSISDN 
(Mobile Subscriber ISDN number) as well as to the location 
information (VLR number) , basic telecommunications 
services subscriber information, service restrictions and 
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supplementary services etc. 

Therefore Figure 3 can be seen to disclose also a SIM 
(Subscriber Identification Module) card 34 inserted within 
5 the MS 1. The telephone company usually uses the SIM for 
controlling payments and location of the user. Thus the 
SIM card 34 has to be connected to the MS 1 before taking 
it into use, and making telephone calls. The MS 1 of 
Figure 3 includes further a MS PAD controller 35 (Mobile 

10 Station Personal Authentication Device controller) . From 
these the SIM 34 may be used in the invention as the means 
for identifying the user and/or including a secret or 
several secrets, and the MS PAD controller 35 is used for 
controlling the authentication operations. In addition to 

15 the general control of the authentication procedure, the 
controller 35 may, eg., be arranged to make all the 
calculations relating the various encryption operations. 
The arrangement: in which the SIM 34, which is controlled 
by the MS FAD controller 35, can be utilized in the 

20 authentication procedure varies. Examples thereof are 

shortly explained in the following.- 
-* 

Instead of the above referred arrangement utilizing SMS 
services, the transactions can also be acknowledged such 

25 that the application, such as the banking service or 
another commercial service paid by an electronic 
transaction, sends the details or tH« transaction to the 
MS PAD 35 as a data signal through the mobile network. 
The correctness of the signal can be ensured by means of a 

30 chcckoum calculated by the MS PAD 3 5 in accordance with a 
predefined algorithm and utilizing the secret of the SIM 
34 : the checksum has to match .with the sum displayed by 
the user terminal 16. if the user accepts the 
transaction, he acknowledges it and gives a permission for 

35 the MS PAD 35 to '[sign 11 the message signal 26 from the 

application by using user's secret (eg. when using public 
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key encryption and a non- repudiation is required) or using 
a secret shared, with the application. Thereafter the 
application will proceed as requested by means of the user 
interface. According to one embodiment, the secret or 
5 secrets of the SIM 34 can also be used for the encryption 
of the messages and/or signaling between the application 
and the MS . 

Figure 6 discloses an alternative embodiment for Figure 2. 

10 In this embodiment the user interface 16 is in a form of 
an ordinary telephone terminal connected to the PSTN 2 0 in 
a per se known manner. The PSTN is further connected to 
intelligent network services { IN) 6 0 which forms the 
application in this embodiment. The mobile station 1 

15 includes a PAD controller 35 and a SIM 34 as described 
above in connection with Figure 3. According to one 
embodiment MS PAD pairs, which contain a predefined pair 
of. a service identifier for the given service and a 
personal secret, are stored within the PAD controller. 

20 These pairs may be used, eg., in the following manner. 

T.he user accesses a service in said IN by establishing « 
telephone call to the service (arrow 21) . The application 
challenges the user with -a number given as a voice 
25 message, or by means of a possible display on said 

telephone terminal (arrow 61) . The user keys in this 
challenge together flJjrtsi) a specific number for the service 
to the MS by the keypad (arrow • whereafter the PAD 
controller accomplishes the necessary calculat ioils, 
30 according to predefined algorithm to receive a further 

number strings . In this calculation the secret stored to 
the SIM for that particular user may form a part of the 
algorithm. This secret may be either application 
specific secret or a secret of the PLMN . The result of 
35 the calculation is then fed in to the user ^terface 16 

(arrow 62) , and transmitted "to the IN service ^ question 
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30 



through the PSTN 20. In case this matches to the expected 
value, the IN service 60 allows the user to initiate the 
use thereof by the fixed line terminal 16. 

5 The above mentioned embodiment can be used, eg. when 
paying telephone calls or services obtained through any 
ordinary POTS line telephone. For instance, this enables 
an arrangement in which calls by any telephone terminal 
are charged from the mobile telephone subscription (ie. 

10 from the holder of a particular SIM card) . The mobile 
subscribers may find this service useful, eg., in 
instances where the calls made by the mobile telephone are 
more expensive than calls by an ordinary POTS telephone, 
or when the MS 1 is not within an area of any such mobile 

15 network into which the user could have a proper radio 
connection . 

According to one additional embodiment (noc shown) the 
mobile station 1 and the user interface 16 are capable of 

20 directly communicating with each other through suitable 
ooerational connection, such as a radio connection, an 
infrared connection or a fixed conduit connection with 
necessary couplings. This reduces the risk for mistyping 
errors which the user might do when acting as a "link" 

25 between the MS 1 and the user interface 16. 

According to one alternative a mobile station is arranged 
to receive more than one SIM card 34. 3y means of this, 
one single mobile station could be used for different 
authentication purposes. For example, a user could have 
three different SIMs: one for the authentications required 
by his work, one for the personal needs, and one for a 
still further need, eg. for a "chairman of an 
association" . Each of the SIMs may have a telephone 
35 number, alarm tone etc. of their own. 
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According to a further alternative the MS 1 communicates 
through a PLMN with the application, and the messages 
and/or signaling required in this communication is 
encrypted using the secret or secrets of the SIM. This 
enables a secure communications using only one 
communications network, ie. the PLMN, as* the secret of the 
SIM is unique, and it is not possible for third parties to 
obtain information contained in the signaling or to break 
into the signaling. 



10 



A further embodiment of the present invention is now 
explained with reference to Figures 1 and 7. Figure 7 
. discloses a schematic cell map of an arbitrary geographic 
area, which is divided into a plurality of contiguous 

15 radio coverage areas or cells. While the system of Figure 
7 is illustrated so as to include only ten cells (CI to 
CIO) , the number of cells may in practice be larger. A 
base station is associated with and located within each of 
the cells, these base stations being designated as BS1 to 

20 BS10, respectively. The base stations are connected to 
the base station subsystems (BSS 6 of Figure 1) . A cell 
may also cover one or several base stations. The cells 
a*re grouped into four groups A to D, wherein each group 
may include one or more cells, as is marked by 

25 corresponding markings. 

Each group is seen by the system as one unit, ie . one 
area, such that four different cell categories A to B are 
provided.' The purpose of this is to illustrate that the 

30 cells may be divided into different authentication 

categories, or classes. The idea behind this is that the 
authentication data within the authentication database may 
include restrictions which do not allow the user to access 
the application in case he is not situated within a 

35 certain predefined cell area. For example, if a company 
uses a MS of an employee for authentication, it is 
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possible to limit the area such that the authentication 
possibility can be restricted to be allowed only in those 
cells (eg. within the area A) which are near to the 
office of the company. 

The above can be easily implemented by means of the 
visitor location register VLR, designated by 8 in Fig. 1. 
The mobile station (MS) 1 or 2 roaming in the area of the 
MSC is controlled by the VLR 8 which is responsible for 
this area. When the MS 1 or 2 appears in the location 
area the VLR initiates an updating procedure. The VLR 
has also a database which includes, eg., the IMSI, MSISDN 
and location area in which the MS is registered according 
to eg , GSM 09.02 specification. So-called cell global 
identification includes further a cell identity, and is 
included in the messages between the MS 1 and the MSC 10. 
This information may be used as an identification 
indicator to find the mobile station MS 1 location, which 
is then utilized in this embodiment. 

It is noted herein that the mobile station can be any kind 
of aoparatus providing a possibility for mobile 

•,~=fio-c; for a user other than the mobile telephone 
communications ror a usci ^<_n^. 

1 or the integrated unit of mobile telephone and a 
computer 2. The latter arrangement is sometimes aiso 
referred to as a "communicator". One example of other 
suitable mobile station is a pager, ie . the "beeper- 
capable' of displaying a character string. What is 

important is that the mobile station is capable of 
, receiving and/or transmitting desired information, which 

in some instances may even be in the form of text or voice 

messages only instead of a specific authentication signal 

or code . 

5 in addition, in the above examples the application 45 is 
arranged to provide linking between the two communications 
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networks such that they both can be used for the 
connection of the user to the application. However, this 
may well be accomplished by some other party. For 
instance, the ISP or similar service provider or the 
telecommunications network operator may operate as an 
authenticating organization and/or provide the linking 
between the two communications networks, and provide a 
secure connection to the actual application. 

Thus, the invention provides an apparatus and a method by 
which a significant improvement can be achieved in the 
area of authentication. The arrangement according to the 
present invention is easy and economical to realize by per 

se known components and is reliable in use. It should be 

noted that the foregoing examples of the embodiments of 
the invention are not intended to restrict, the scope of 
the invention defined in the appended claims. All 
additional embodiments, modifications and applications 
obvious to those skilled in the arc are thus included 
within the spirit and scope of the invention as set forth 
by the claims appended hereto. 



JNSDOCID: <WO 9944114A1 J_> 



WO 99/44114 



PCI7EP99/00763 



-25- 



Claims 

1. A method for authenticating a user to an application, 
5 the application being available to the user through a 

first communications network, the method comprising: 

establishing a connection between the application and 
a user interface through said first communications network 
so as to enable a user to access the application; and 
10 authenticating the user to said application by means 

of a mobile station communicating with the application 
through a second communications network. 

2. A method according to claim 1, wherein the step of 
15 authenticating comprises using the mobile station to 

verify the identity of the user as the user accesses. the 
application by the user interface. 

3. A method according to claim 1, wherein the step of 
20 authenticating comprises using the mobile station for 

acknowledging a transaction or proceeding which the user 
-has previously requested from the application through the 
user interface. • 

25 4. A method according to any one of the preceding claims, 
wherein the mobile station is a cellular telephone and 
said second communications network comprises a digital 
cellular network. 

30 5. A method according to any one of the preceding claims 
and comprising utilizing a secret of a Subscription 
Identification Module (SIM) of the mobile station for 
encryption of signalling associated with the 
authentication step. 



o . 



A method according to any one of the preceding claims 
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wherein a Subscription Identification Module (SIM) of the 
mobile station is used for providing the identity of the 
user. 

5 7. A method according to claim 6 and comprising the step 
of charging the costs of the connection from the user 
interface to the application to the holder of the 
subscription identified by the SIM. 

10 8. A method according to any one of the preceding claims, 
wherein at lease part of the signaling between the 
application and the mobile station is in the form of short 
message system text messages. 

15 9. A method according to any one of the preceding claims 
and comprising uhe step of using area location information 
of the mobile station as one parameter of the 
authentication procedure. 

20 10. A method of providing an authentication to an 

application available to a user through a communications 
network, the method comprising: 

establishing a connection between the application and 
a user interface through said communications network so as 

25 to enable access of a user to the application; and 

providing an authentication to said application by 
means of a mobile station such that a secret of a 
Subscription Identification Module (SIM) of the mobile 
station is utilized in encryption operations of the 

30 authentication . 

11. An arrangement for providing an authentication to an 
application provided by an application provider through a 
communications network, comprising: 
35 a user interface; 

a connection between the application and the user 
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interface through said communications network so as to 
enable use of the application; and 

means for authenticating the use of the application, 
wherein said means for authenticating comprises a mobxle 
5 station communicating through a mobile communications 

network, and a link between the application implemented by 
means of the communications network and the mobxle 
communications network. 

10 12. An arrangement according to claim 11, wherein the 
mobile station is a cellular telephone and the mobxle 
communications network is a digital cellular network. 

13 An arrangement according to claim 11 or 12, wherein 
„ authentication signaling to and from the mobile, statxon 
ar~ in the form of text messages provided by a short 
message system (SMS) of the mobile communications network. 

14 An' arrangement according to any one of claims 11 to 
,0 13 ! wherein che mobile station comprises a mobile statxon 
personal authentication device (MS PAD) arranged to 
control the authentication procedure, and a 
identification module (SIM) including a secret and bexng 

, ho the MS PAD, wherein the secret 

operationally connected to the Mb 

25 of the SIM is arranged to be" utilized in the 
authentication procedure. 

1= an arranoemenc according to any one of claims 11 to 
ill characterised in that the application is a bankxng 
30 service, an electronic shopping service, or some other 
commercial service requiring an acknowledgment for an 
electronic transaction. 

1«. A mobile station for providing an authentication to an 
35 application provided through a communications network, 
wherein: 
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the application is accessed by means of a user 
interface connected to the communications network; and 

said mobile station uses a different communications 
network for the communications than the user interface, 
5 and the mobile station is used for authenticating the use 
of said application accessed by the user interface. 

17. A mobile station according to claim 16 and comprising 
an integrated mobile station personal authentication 

10 device (MS PAD) arranged to control the authentication 
procedure . 

18. A mobile station according to claim 16 or 17, wherein 
the station is a digital mobile telephone and comprises a 

15 subscription identification module (SIM) including a 

secret, wherein the secret of the SIM is arranged to be 
utilized in the authentication procedure. 

19. A mobile station according to claim 18 and comprising 
20 at least one additional SIM. 

20. A mobile station according to claim 16 or 19 and 
comprising means for directly interfacing with the user 
interface,, such as by an infrared or radio transceiver 

25 capable of communicating with the user interface. 
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